Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is the EU AI Act and who does it apply to?
- How does the Act classify AI risk?
- Which AI practices are prohibited today?
- What counts as a high - risk AI system?
- What obligations do high - risk AI providers face?
- How are general - purpose AI models regulated?
- When do transparency duties apply?
- What is the implementation timetable?
- How is the Act enforced and what are the penalties?
- Are there any exemptions?
- How does the EU AI Act affect non - EU companies?
- What steps should developers take today?
- Where can I find more detailed guidance?
Key takeaways
- The EU AI Act is a directly - applicable regulation with extraterritorial reach; any AI system used in the EU must comply.
- It uses a risk - based classification: unacceptable, high, limited (transparency), and minimal risk.
- Prohibited practices are enforceable from 2 Feb 2025 and carry fines up to €35 million or 7 % of worldwide turnover.
- High - risk AI systems face the most demanding obligations, including a conformity assessment and registration in the EU AI database.
- General - purpose AI models are regulated regardless of downstream use; systemic - risk models (≥ 10^25 FLOPs) have extra safety duties.
- Transparency obligations for chatbots and synthetic media start on 2 Aug 2026.
What is the EU AI Act and who does it apply to?
The EU AI Act is a Regulation that applies automatically across all EU member states, so no national transposition is required. It covers any AI system placed on the EU market, put into service, or whose output is used in the EU, even if the provider is located outside the Union.
How does the Act classify AI risk?
The Act defines four risk tiers. Unacceptable - risk AI is banned outright. High - risk AI must undergo a full conformity assessment, maintain technical documentation, and implement post - market monitoring. Limited - risk AI (transparency) requires a clear notice that users are interacting with AI or that content is AI - generated. Minimal - risk AI has no specific obligations beyond general AI - literacy duties.
Which AI practices are prohibited today?
From 2 Feb 2025 the following practices are illegal and subject to the highest fines:
- Harmful AI - driven manipulation and deception.
- Exploitation of vulnerabilities of specific groups.
- Social scoring by public authorities.
- Real - time remote biometric identification in public spaces for law - enforcement.
- Untargeted scraping of facial - recognition data.
- Emotion - recognition in workplaces or education.
- Biometric categorisation that infers protected characteristics.
- Predictive policing or individual criminal - offence risk assessment.
What counts as a high - risk AI system?
Annex III lists use - cases that automatically trigger high - risk status, such as:
- Biometric identification (e.g., facial - recognition).
- Critical infrastructure (energy, transport, water).
- Education and vocational training tools.
- Employment and worker - management systems.
- Access to essential services like credit scoring or insurance risk.
- Law - enforcement and public - security applications.
- Migration, asylum and border - control tools.
- Administration of justice and democratic processes.
What obligations do high - risk AI providers face?
High - risk providers must:
- Implement a risk - management system covering data governance, accuracy, robustness and cybersecurity.
- Produce and keep up - to - date technical documentation and logs.
- Ensure human oversight and clear fallback mechanisms.
- Conduct a conformity assessment (often via a notified body) before market placement.
- Register the system in the EU AI database and display the CE - type conformity mark where applicable.
How are general - purpose AI models regulated?
General - purpose AI (GPAI) models are defined as large - scale models capable of many tasks. Baseline duties (effective 2 Aug 2025) require:
- Technical documentation of the model.
- Information for downstream developers about intended use and limitations.
- A copyright - policy statement.
- A summary of the training - data content. If a model exceeds the systemic - risk threshold (≥ 10^25 floating - point operations) it must also:
- Perform state - of - the - art model evaluation and adversarial testing.
- Conduct a systemic - risk assessment and mitigation plan.
- Report serious incidents to the AI Office.
- Apply robust cybersecurity controls.
When do transparency duties apply?
Article 50 introduces transparency duties on 2 Aug 2026. Providers must:
- Notify users when they interact with a chatbot or any system that communicates with natural persons.
- Attach a machine - readable label to AI - generated audio, image, video or text indicating its synthetic origin.
- Inform users of any emotion - recognition or biometric - categorisation functions.
What is the implementation timetable?
| Date | Milestone |
|---|---|
| 1 Aug 2024 | Regulation enters into force, AI Office and AI Board created |
| 2 Feb 2025 | Prohibited practices and AI - literacy duties become enforceable |
| 2 Aug 2025 | Baseline obligations for GPAI models apply |
| 2 Aug 2026 | General application of the Act; transparency duties enforceable |
| 2 Dec 2027 | High - risk Annex III obligations for stand - alone systems become mandatory |
| 2 Aug 2028 | High - risk Annex I obligations for AI as safety component of regulated products become mandatory |
How is the Act enforced and what are the penalties?
National market - surveillance authorities supervise providers and may delegate conformity assessments to notified bodies. The European AI Office coordinates EU - wide enforcement, especially for GPAI models. Penalties are tiered:
- Violations of prohibited practices: up to €35 million or 7 % of worldwide annual turnover (whichever is higher).
- Other infringements (high - risk, transparency, GPAI duties): up to €15 million or 3 % of worldwide turnover.
- Supplying false information to authorities: up to €7.5 million or 1 % of turnover. SMEs receive proportionally smaller fines.
Are there any exemptions?
Yes. The Act does not cover military and defence AI, pure research without market application, or personal non - professional use of AI systems.
How does the EU AI Act affect non - EU companies?
Because the regulation applies to any AI output used in the EU, non - EU providers must assess whether their systems fall into any risk tier and implement the corresponding obligations. Failure to do so can lead to significant fines and market restrictions.
What steps should developers take today?
- Map your AI portfolio - Identify which systems are potentially high - risk, limited - risk or GPAI.
- Perform a gap analysis - Compare current practices against the obligations listed in Articles 8 - 21 (high - risk) and Article 50 (transparency).
- Create or update technical documentation - Include data - governance, risk - management, and human - oversight procedures.
- Set up a conformity - assessment process - Engage a notified body early if you have high - risk AI.
- Implement transparency mechanisms - Add clear UI notices and machine - readable labels for synthetic media.
- Monitor the AI Office and national authorities - Stay informed about guidance, especially for GPAI systemic - risk thresholds.
Where can I find more detailed guidance?
- Official EU summary: https://eur - lex.europa.eu/summary/EN/legissum%3A4762484
- High - level overview of risk tiers: https://artificialintelligenceact.eu/high-level-summary/
- Detailed obligations for high - risk AI: https://confir.eu/eu-ai-act/summary
- Timeline and governance details: https://www.regulatoryai.eu/what-is-the-eu-ai-act/
- EU AI Office and AI Board information: https://www.consilium.europa.eu/en/policies/artificial-intelligence-act/
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.